Courseiva
mediumMultiple Select

200-901 Practice Question: Which TWO of the following are recommended…

Which TWO of the following are recommended practices for securing a CI/CD pipeline in a DevOps environment? (Choose two.)

⚠ Common exam trap

Cisco often tests the misconception that security testing can be deferred to post-production (Option C) or that shared credentials simplify management (Option E), but the correct answers emphasize proactive security (scanning early) and credential isolation (vault injection).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store secrets and credentials in a secure vault and inject them at runtime

Option A is correct because storing secrets and credentials in a dedicated secure vault (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) and injecting them at runtime avoids hardcoding sensitive data in source code, pipeline configs, or environment files, reducing the risk of credential leakage and enabling centralized rotation and auditing. Option D is correct because integrating container image scanning (e.g., Trivy, Clair, Anchore, or native registry scanners) into the build pipeline detects known CVEs in base images and dependencies early, allowing vulnerabilities to be remediated before artifacts are promoted to production. Option B is not recommended because granting all developers write access to production violates least privilege and separation of duties, increasing the risk of accidental or malicious changes. Option C is wrong because security testing must shift left and run before production deployment; testing only after deploying to production exposes live systems to unverified vulnerabilities. Option E is wrong because reusing a single API token across all pipeline stages removes stage isolation, so compromise of one stage grants broad access and prevents fine-grained, least-privilege scoping and revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Store secrets and credentials in a secure vault and inject them at runtime

    Why this is correct

    Hard-coded credentials in pipeline definitions, scripts or repositories leak through logs and version history. A vault keeps secrets encrypted and access-controlled, injecting them only into the running job, so the pipeline never persists plaintext credentials in build artefacts or source control.

  • ✗

    Grant all developers write access to the production environment to enable faster fixes

    Why it's wrong here

    Blanket write access to production removes the approval gate and separation of duties that pipeline security depends on, letting any compromised developer account push straight to live. It is tempting because rapid hotfixes are a genuine operational need, and this would suit a break-glass emergency role that is time-bound, logged and separately approved.

  • ✗

    Deploy code to production first, then run security tests to check for issues

    Why it's wrong here

    Running security tests only after production deployment means vulnerable code is already live and exploitable before detection. It is tempting because shift-left scanning can slow the pipeline, and this would be acceptable only for non-blocking post-deployment monitoring, not as the primary security gate, which belongs before release.

  • ✓

    Scan container images for known vulnerabilities as part of the build pipeline

    Why this is correct

    Base images and dependencies frequently carry known CVEs that survive into production. Scanning images during the build stage detects vulnerable packages before the artefact is pushed to a registry, allowing the pipeline to fail fast and block deployment of compromised images.

  • ✗

    Use the same API token for all pipeline stages to simplify authentication

    Why it's wrong here

    Reusing one API token across every stage means a compromise at build time grants deploy and production access, defeating least privilege. Scoped, per-stage credentials limit blast radius. A single token suits only isolated, non-production pipelines where all stages share identical trust and no promotion to protected environments occurs.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.